• A proof-of-concept (PoC) exploit has been released for a critical vulnerability in the secure boot chain of the Nothing Phone (2a) and CMF Phone 1, potentially affecting other devices using MediaTek systems-on-a-chip (SoCs).

    The exploit, named Fenrir and published by researcher R0rt1z2, allows for arbitrary code execution at the highest privilege level, effectively breaking the secure boot process.

    The vulnerability stems from a logical flaw in the MediaTek boot chain, where a key component is not properly verified when the bootloader is in an unlocked state.

    The vulnerability resides in the Preloader stage of the MediaTek boot process. When a device’s bootloader is unlocked (seccfg is set to unlocked), the Preloader fails to verify the cryptographic signature of the bl2_ext partition.

    This oversight is critical because bl2_ext is responsible for verifying all subsequent components in the boot chain.

    The Preloader transfers execution to bl2_ext while still operating at Exception Level 3 (EL3), the highest privilege level in ARM architecture.

    An attacker can therefore patch bl2_ext to bypass all further signature checks, causing a total collapse of the chain of trust and allowing the loading of unverified and malicious code.

    Nothing Phone Code Execution Vulnerability

    By exploiting this flaw, an attacker can achieve code execution at EL3, granting them deep control over the device before the main operating system even begins to load.

    The PoC demonstrates this by patching a single function, sec_get_vfy_policy(), to always return a value of 0, tricking the bootloader into believing that all subsequent images are verified.

    The released exploit includes a payload that can register custom fastboot commands, control the device’s boot mode, and dynamically call native bootloader functions.

    Additionally, the PoC can spoof the device’s lock state, making it appear as “locked” to pass strong integrity checks even when the bootloader is unlocked.

    The researcher notes that while the current payload cannot modify memory at runtime due to MMU faults, the exploit provides a powerful foundation for further development.

    Affected Devices And Mitigation

    The exploit has been confirmed to work on the Nothing Phone (2a) (codenamed “Pacman”) and the CMF Phone 1 (codenamed “Tetris”).

    The developer of the exploit also notes that the Vivo X80 Pro is affected by a similar, and potentially more severe, vulnerability where bl2_ext is not verified even with a locked bootloader.

    The issue is believed to be present in other MediaTek devices that use “lk2” as their secondary bootloader.

    The researcher has issued a strong warning, stating that any attempt to use the exploit can permanently damage or “brick” a device if not performed correctly.

    Users are advised to exercise extreme caution, as the process involves flashing a modified bootloader image that can lead to irreversible hardware failure.

    Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

    The post PoC Exploit Released For Nothing Phone Code Execution Vulnerability appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researcher Norbert Szetei published the final installment of his deep-dive into the ksmbd filesystem module, culminating in a working proof-of-concept exploit targeting CVE-2025-37947. Unlike earlier use-after-free candidates that required complex race conditions or depended on external factors, this vulnerability offers a deterministic out-of-bounds (OOB) write primitive. Szetei’s PoC was tested on Ubuntu 22.04.5 LTS […]

    The post PoC Released for Linux Kernel ksmbd Filesystem Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Corporate data security faces an unprecedented crisis as new research reveals widespread employee misuse of generative AI platforms.

    A comprehensive study examining enterprise browsing behavior has uncovered alarming patterns of sensitive data exposure across organizations worldwide.

    The research, based on real-world telemetry from enterprise browsers, demonstrates that artificial intelligence tools have become the primary vector for unauthorized data transfer from corporate environments.

    The study exposes how rapidly generative AI has integrated into workplace routines, with 45% of enterprise users now actively engaging with AI platforms.

    ChatGPT dominates this landscape, capturing 43% of overall employee usage and representing 92% of all generative AI activity within organizations.

    This remarkable adoption rate places AI tools alongside established enterprise categories like email and file sharing in terms of daily utilization.

    Most concerning is the scale of sensitive information exposure through these platforms. The research reveals that 77% of employees regularly paste data into generative AI tools, with 82% of this activity occurring through unmanaged personal accounts that bypass corporate oversight.

    This behavior has positioned generative AI as the leading channel for corporate-to-personal data exfiltration, accounting for 32% of all unauthorized data movement outside sanctioned environments.

    LayerX Security analysts identified these patterns through comprehensive monitoring of enterprise browser activity, providing unprecedented visibility into employee interactions with AI platforms.

    Their research methodology involved deploying security solutions directly within user browsers across multiple large-scale enterprises, capturing complete visibility into data flows between corporate systems and external AI services.

    The financial and compliance implications are staggering, with 40% of files uploaded to generative AI platforms containing personally identifiable information (PII) or payment card industry (PCI) data.

    Similarly, 22% of data pasted into these tools includes sensitive regulatory information. This exposure creates substantial risks for organizations subject to data protection regulations like GDPR, HIPAA, or SOX compliance requirements.

    Unauthorized Access Patterns Drive Enterprise Blindspots

    The research reveals a critical identity management crisis within enterprise environments, where traditional access controls have failed to contain employee behavior.

    Personal account usage dominates high-risk categories, with 67% of generative AI access occurring through unmanaged accounts that exist outside corporate identity systems.

    This pattern extends beyond AI tools, affecting business-critical applications including Salesforce (77% non-corporate access), Microsoft Online (68% non-corporate), and Zoom (64% non-corporate).

    Even when employees use corporate credentials, authentication weaknesses persist across enterprise systems. The study found that 83% of ERP logins and 71% of CRM access occurs without single sign-on (SSO) federation, effectively treating corporate accounts like personal ones.

    This creates massive visibility gaps where sensitive business workflows operate outside IT oversight and security controls.

    The copy-paste behavior represents the most dangerous data transfer method, as it bypasses traditional data loss prevention (DLP) systems entirely.

    Employees average 46 paste operations daily, with personal accounts generating an average of 15 pastes per day, including at least 4 containing sensitive data.

    Popular destinations include ChatGPT, Google services, Databricks, LinkedIn, Snowflake, and Slack, demonstrating how corporate information flows into diverse external platforms through routine productivity activities.

    Chat and instant messaging applications compound these risks, with 87% of activity occurring through unmanaged accounts while 62% of users paste PII/PCI data into these platforms.

    This combination of high personal account usage and frequent sensitive data exposure makes messaging apps among the most dangerous channels for unauthorized information transfer.

    Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

    The post 77% of Employees Share Company Secrets on ChatGPT Compromising Enterprise Policies appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Russian hackers’ adoption of artificial intelligence (AI) in cyber attacks against Ukraine has reached a new level in the first half of 2025 (H1 2025), the country’s State Service for Special Communications and Information Protection (SSSCIP) said. “Hackers now employ it not only to generate phishing messages, but some of the malware samples we have analyzed show clear signs of being generated

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have discovered a sophisticated evolution of the ClickFix attack technique that leverages browser cache smuggling to covertly place malicious files on target systems without traditional file downloads. This advanced social engineering campaign specifically targets enterprise users through fake Fortinet VPN compliance pages, demonstrating how threat actors continuously adapt their methods to evade detection. […]

    The post Hackers Enhance ClickFix Attack Using Cache Smuggling to Stealthily Download Malicious Files appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers have released a full proof-of-concept (PoC) exploit for a high-severity vulnerability in the Linux kernel’s ksmbd module, demonstrating a reliable path to local privilege escalation.

    The vulnerability, tracked as CVE-2025-37947, is an out-of-bounds write that can be leveraged by an authenticated local attacker to gain complete root control over a vulnerable system.

    This discovery, detailed by researchers at Doyensec, is the culmination of extensive vulnerability research into the kernel-level Server Message Block (SMB) server, which has seen increased adoption in recent Linux versions.

    The public release of the exploit code underscores the practical risk posed by this flaw to systems running the affected kernel module.

    The root cause of CVE-2025-37947 lies within the ksmbd_vfs_stream_write() function, which is responsible for handling write operations to file streams using extended attributes.

    The vulnerability can be triggered by an authenticated user on systems where ksmbd is configured with a writable share and the streams_xattr VFS module is enabled.

    The flaw stems from improper size validation when a user-supplied position and data count surpass the XATTR_SIZE_MAX limit of 65,536 bytes.

    Although the code truncates the allocation size for the buffer, it fails to adjust the count for the memcpy operation accordingly.

    This logic error allows an attacker to write a controlled amount of data past the boundary of the allocated kernel buffer, leading to memory corruption in an adjacent memory region.

    From Bug To Root Privilege Escalation

    The Doyensec researchers detailed how this out-of-bounds write primitive can be escalated into a full root exploit on a modern Linux system, specifically Ubuntu 22.04.5 LTS.

    The exploitation strategy involves a sophisticated, multi-stage process that begins with heap shaping to manipulate the kernel’s memory layout.

    By carefully allocating and freeing kernel objects, the attackers could position a controlled victim object, a msg_msg kernel message structure, directly after the vulnerable buffer.

    The out-of-bounds write is then used to corrupt the msg_msg header, creating a use-after-free (UAF) condition.

    This UAF primitive is subsequently used to leak kernel memory addresses, bypassing Kernel Address Space Layout Randomization (KASLR).

    With KASLR defeated, the attackers reuse the UAF to overwrite a function pointer in a pipe_buffer object, hijacking the kernel’s control flow to execute a ROP chain that grants them root privileges.

    Proof-of-Concept Exploit Released

    In their disclosure, the researchers published the complete local privilege escalation exploit on GitHub. This allows other security professionals to analyze the attack and validate its impact on their systems.

    While the current exploit focuses on local access, the researchers noted that remote exploitation is significantly more challenging, as it would likely require a separate information disclosure vulnerability to defeat KASLR and make heap grooming reliable.

    This finding is part of a broader security audit of ksmbd by Doyensec, which has previously uncovered other critical vulnerabilities, including several unauthenticated race conditions and memory exhaustion flaws.

    System administrators are advised to review their use of ksmbd and ensure that their systems are patched against CVE-2025-37947 as updates become available from their Linux distribution providers.

    Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

    The post Linux Kernel ksmbd Filesystem Vulnerability Exploited – PoC Released appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitLab has issued a critical security update to address several denial-of-service (DoS) vulnerabilities affecting both Community Edition (CE) and Enterprise Edition (EE). Self-managed installations should upgrade immediately to versions 18.4.2, 18.3.4, or 18.2.8. GitLab.com already runs the patched versions, and GitLab Dedicated customers are unaffected. The GitLab team delivers scheduled releases twice a month, on […]

    The post GitLab Releases Security Update to Patch Multiple DoS-Enabling Vulnerabilities appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • GitLab has released important security updates. The new versions are 18.4.2, 18.3.4, and 18.2.8 for both Community Edition (CE) and Enterprise Edition (EE).

    These updates fix several vulnerabilities that could lead to denial-of-service (DoS) attacks and allow unauthorized access.

    All self-managed GitLab installations are strongly advised to upgrade promptly to mitigate potential disruptions. GitLab.com and GitLab Dedicated customers are already fully protected by these patches.

    The patched releases address several newly discovered vulnerabilities affecting both authenticated and unauthenticated users. These issues, spanning various attack vectors, underscore the ongoing risk to code repositories and development pipelines if left unpatched.

    GitLab’s standard practice ensures issues are only publicly documented 30 days after patch deployment, emphasizing the need for proactive upgrades to preserve security posture.

    Multiple Vulnerabilities Patched

    Security researchers and GitLab’s internal team have identified four main issues in this update, each posing unique risks:

    CVE-2025-11340: GraphQL Mutation Authorization Bypass

    This high-severity vulnerability (CVSS 7.7) allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records due to incorrect scoping in GraphQL mutations.

    Exploitation could lead to tampering with vulnerability details, straining governance and compliance efforts. Impacted versions include GitLab EE 18.3 to 18.3.4 and 18.4 to 18.4.2. Discovered internally by GitLab.

    CVE-2025-10004: Denial of Service via GraphQL Blob Requests

    Assigned a CVSS score of 7.5, this remote flaw impacted versions from 13.12 through 18.2.8, 18.3 up to 18.3.4, and 18.4 up to 18.4.2. By sending specially crafted GraphQL requests for large repository blobs, attackers could exhaust server resources, making a GitLab instance unresponsive. No authentication is required, substantially widening its attack surface.

    CVE-2025-9825: Unauthorized Access to Manual CI/CD Variables via GraphQL

    This medium-severity bug (CVSS 5.0) exposed sensitive manual CI/CD variables to authenticated users lacking project membership, simply by querying the GraphQL API. Versions affected range from 13.7 to 18.2.8, and pre-patched releases of 18.3 and 18.4.

    CVE-2025-2934: DoS via Malicious Webhook Endpoints in GitLab CE/EE

    Affecting all versions from 5.2 up to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2, this moderate risk (CVSS 4.3) stemmed from a Ruby Core library flaw. Attackers could configure webhooks to send malicious HTTP responses, destabilizing GitLab servers. The issue was responsibly disclosed in July 2025.

    CVE IDVulnerability TitleSeverityCVSS ScoreImpacted Versions
    CVE-2025-11340GraphQL Mutations Auth Bypass (EE)High7.718.3 – 18.3.4, 18.4–18.4.2
    CVE-2025-10004DoS via GraphQL Blob Type (CE/EE)High7.513.12–18.2.8, 18.3–18.3.4, 18.4–18.4.2
    CVE-2025-9825Manual Jobs Auth Flaw (CE/EE)Medium5.013.7–18.2.8, 18.3–18.3.4, 18.4–18.4.2
    CVE-2025-2934DoS via Webhooks (CE/EE)Medium4.35.2–18.2.8, 18.3–18.3.4, 18.4–18.4.2

    Mitigations

    GitLab strongly urges all organizations administering self-managed or on-premise deployments to upgrade immediately to the newly released versions to avoid system downtime and unauthorized data manipulation.

    Delaying updates increases risks of disruption, data leakage, and exploit-driven escalation attacks. GitLab provides best practices and upgrade instructions on their official releases and security blogs.

    Maintaining prompt patch hygiene is essential for development teams and enterprises relying on GitLab for source code, CI/CD, and collaborative software workflow management.

    Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today

    The post GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A newly spotted Python remote access trojan (RAT) on VirusTotal employs advanced polymorphic and self-modifying techniques, allowing it to alter its code signature on every execution and evade detection. Security researchers examining VirusTotal submissions identified a suspicious Python RAT (SHA256:7173e20e7ec217f6a1591f1fc9be6d0a4496d78615cc5ccdf7b9a3a37e3ecc3c) that scored only 2/64 on VT. What sets this sample apart are three distinct function […]

    The post Polymorphic Python Malware That Mutates Every Time It Runs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Threat actors are actively exploiting a critical security flaw impacting the Service Finder WordPress theme that makes it possible to gain unauthorized access to any account, including administrators, and take control of susceptible sites. The authentication bypass vulnerability, tracked as CVE-2025-5947 (CVSS score: 9.8), affects the Service Finder Bookings, a WordPress plugin bundled with the

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶